AUTO-UPDATED

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

South Korean and U.S. cybersecurity agencies have issued a joint warning regarding the Gunra ransomware, which targets critical infrastructure through exploited Fortinet vulnerabilities and sophisticated double-extortion tactics.

Key Points

  • Gunra ransomware has compromised 51 victims globally since April 2025, primarily across South Korea, Brazil, Thailand, Hong Kong, and Spain.
  • Attackers gain initial access by exploiting vulnerabilities in Fortinet FortiOS and FortiProxy appliances, specifically CVE-2024-55591 and CVE-2025-24472.
  • The group utilizes a double-extortion model, exfiltrating sensitive data before encrypting systems and threatening to publish stolen information if ransoms remain unpaid.
  • Technical tactics include using Impacket libraries for lateral movement, credential dumping from domain controllers, and bypassing multi-factor authentication on VDI portals.
  • Security researchers have observed potential operational overlaps between Gunra and state-sponsored actors, including the North Korean-linked Lazarus Group.

Why it Matters

The emergence of Gunra highlights a growing trend of collaboration between financially motivated ransomware gangs and state-sponsored threat actors. Organizations must prioritize patching internet-facing appliances and implementing immutable backups to mitigate the risk of these increasingly sophisticated, multi-stage cyberattacks.
Internet Published by info@thehackernews.com (The Hacker News)
Read original